CISO - Chief Information Security Officer

il y a 19 heures


Paris, France Shift Technology group Temps plein

CISO - Chief Information Security Officer France - Paris Shift is the leading AI platform for insurance. Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact. Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale and with proven results. Our culture is built on innovation, trust, and a drive to transform the insurance industry through our SaaS platform. We come from more than 50 different countries and cultures and together we are creating the future of insurance. We’re looking for a Chief Information Security Officer (CISO) to join our Technology Leadership Team — someone ready to develop and scale our global security strategy, bring enterprise best practices, and directly influence how we build and protect technology that powers our business and insurance customers worldwide. This role reports to the CTO and works closely with our Executives and Leaders to help shape the next chapter of Shift’s growth. What You'll Do Lead from the front. Roll up your sleeves to design, build, and continuously improve Shift’s global information security program — from strategy to implementation. You’ll define the security roadmap and directly drive its execution, ensuring alignment with our business growth, customer commitments, and risk appetite. Be in the trenches with the business. Partner daily with our teams to embed security into how we sell, build, and deliver. You’ll join customer meetings, shape RFP responses, and give enterprise clients the confidence that their data is protected end-to-end. Build, mentor, and operationalize. Stand up and scale a high-performing security team. Establish clear processes, run tabletop exercises, monitor controls, and drive a security-first culture across engineering, operations, and customer success. Protect without slowing progress. Engineer pragmatic, scalable controls into Shift’s SaaS platform — enabling rapid product development while maintaining enterprise-grade protection and compliance. Stay ahead of threats and regulations. Actively monitor emerging attack vectors, regulatory updates, and technology shifts. Advise the executive team and Board with actionable insights and clear risk assessments that tie directly to business outcomes. What You Bring Holistic Security Leadership and Business Alignment: You bridge risk governance and business strategy. Proven ability to design and lead an enterprise-wide security strategy that balances risk, compliance, and innovation. Proven ability to own, build, and manage a global GRC program, translating the complex intersection of AI (EU AI Act, ISO 42001), Privacy (GDPR, ISO 27701), Health (HITRUST, HDS), and Financial Services (DORA, NYDFS) regulations and standards into practical engineering controls and company-wide processes, while maintaining compliance with core standards like SOC 2 and ISO 27001. Skill in communicating security posture and trade-offs to executives, board members, and customer executives. Deep Technical Expertise in Application and Cloud Security: You understand how software is built and deployed — not just how to secure it after the fact. Hands-on experience of designing, implementing and managing secure SDLC practices, API and microservice security, and cloud-native architectures. Demonstrated expertise in implementing, managing, and tuning modern AppSec tooling (SAST, DAST, SCA, container scanning) and CI/CD pipeline integration. Ability to guide, educate, and influence engineering teams on threat modeling, code-level risks, and secure design principles. DevSecOps Mindset and Automation Experience: You know Security has to be part of development workflows. Demonstrated experience embedding security controls into DevOps pipelines and culture. Direct experience of securing infrastructure-as-code (e.g., Terraform, Kubernetes, AWS CloudFormation). Comfort driving automation and “shift left” initiatives that make secure development faster, not slower. Strong GRC, Risk Management, and Compliance Expertise: Even in a highly technical role, governance and assurance remain foundational. Expertise in risk assessment methodologies, control frameworks, and audit processes. Ability to build compliance programs that scale — translating regulatory obligations into practical, developer-friendly controls. Experience managing third-party risk, vendor security, and customer assurance activities (e.g., security questionnaires, RFPs). About you 15+ years of Info Sec leadership experience, including at least 7 years in senior security roles within SaaS or cloud-first organizations. Strong expertise in cloud security (AWS, Azure, GCP), DevSecOps, identity and access management, and data protection. Proven success leading security in high-growth, multi-national environments. In-depth knowledge of regulatory frameworks and compliance programs (SOC 2, ISO 27001, GDPR, CCPA, etc.). Relevant certifications such as CISSP, CISM, CISA, or CCSP preferred. Fluency in English required, French strongly preferred. Interview Process Technical Round (2 interviews) Business Partner/Stakeholder Interview CEO Interview Benefits To support our permanent, full time employees at every stage of their careers and lives, we provide a competitive total rewards and benefits package. Here are the global benefits we’d like to highlight: Flexible remote and hybrid working options Competitive Salary and a variable component tied to personal and company performance Company equity Multiple Learning and Development opportunities, including Focus Fridays, a half-day each month to focus on learning and personal growth Generous PTO and paid holidays 2 MAD Days per year (Make A Difference Days for paid volunteering) Additional benefits may be offered by country - ask your recruiter for more information. Intern and Apprentice position are eligible for some of these benefits - ask your recruiter for more details. At Shift we strive to be a diverse and inclusive workforce. We welcome applications from and hire people who will contribute to the diversity of our company, without regard to race, color, religion, marital status, age, national or ethnic origin, physical or mental disability, medical condition, pregnancy, genetic information, gender identity or expression, sexual orientation, or other non-merit criteria. Shift Technology is committed to providing reasonable accommodations for qualified individuals with disabilities in our application and employment process. Should you require accommodation, please email accommodation@shift-technology.com and we will work with you to meet your accessibility needs. Please be aware of scammers and only trust correspondence that comes from emails ending in "shift-technology.com". We will never do initial outreach to you via Whatsapp/Text/SMS, never ask for banking information or personal identification numbers (ex. Social Security Number) as part of our recruitment process. Shift Technology does not accept unsolicited CVs from recruiters or employment agencies in response to the Shift Technology Careers page or a Shift Technology social media post. Any unsolicited CVs, including those submitted directly to hiring managers, are deemed to be the property of Shift Technology. #J-18808-Ljbffr



  • Paris, Île-de-France CyberInterim Temps plein

    Company DescriptionCyberInterim is one of the largest global networks of Information Security Experts. Dedicated to addressing complex cybersecurity challenges, CyberInterim provides expertise across industries to ensure an organization's digital security and resilience. The company is committed to delivering tailored solutions and maintaining the highest...


  • Paris 3e, France ATTINEOS INFRASTRUCTURES Temps plein

    **CHIEF OF INFORMATION SECURITY OFFICER (CISO) - F/H** **VOUS NE CONNAISSEZ PAS ENCORE ATTINEOS INFRASTRUCTURES ?** Créée en 2017, Attineos Infrastructures est la société sœur d'Attineos Applications et Attineos Cybersécurité. Des ESN Normandes, 100% décomplexées ! L'entité Attineos Infrastructures accompagne ses clients dans...


  • Paris, France Allego Temps plein

    **This is Allego** Allego provides reliable charging solutions to cities, companies, and consumers. We deliver charging facilities that can be used by all electric cars and every EV driver, providing a seamless charging experience. Our goal is to contribute to zero emission mobility and see to it that EV drivers can charge at the right location with the...


  • Paris, France deepomatic Temps plein

    **The opportunity** We are looking for a Chief Information Security Officer (CISO) to both (i) take the lead of our security strategy and (ii) implement necessary changes, in order to deliver AI to the field service ecosystem in the most secure manner. At Deepomatic, we believe artificial intelligence is the way to unlock the world of tomorrow. We believe...


  • Paris, Île-de-France Shift Technology Temps plein

    Shift is the leading AI platform for insurance.  Shift combines generative, agentic, and predictive AI to transform underwriting, claims, and fraud and risk - driving operational efficiency, exceptional customer experiences and measurable business impact.  Trusted by the world's leading insurers, Shift delivers AI when and where it matters most, at scale...


  • Paris, France Shift Technology group Temps plein

    A prominent AI platform for insurance is seeking a Chief Information Security Officer (CISO) to develop and scale its security strategy. This role involves designing a global information security program, embedding security into business processes, and overseeing a high-performing security team. Candidates should have over 15 years of experience in Info Sec...


  • Paris, France Swile Temps plein

    Swile is the first employee super-app and platform that offers a unified, personalized and modern experience that strengthens engagement at work. But it's also a smart-card that brings together all your benefits: reinvented meal vouchers, gift vouchers to spoil your employees all year round, a mobility advantage to reduce your carbon impact By combining...


  • Paris, Île-de-France SCOR Temps plein

    Job SummaryThe Regional CISO - APAC serves as the primary security leader for the APAC region, reporting to the Group CISO and with a cross-functional reporting line to the APAC CIO. This role is responsible for governing and overseeing the implementation of Group security policies and programs across APAC, ensuring adherence to global standards while...


  • Paris, France Aplo Temps plein

    Paris/France-based (remote possible)About the CompanyAt Aplo, you won’t just do a job - you’ll own outcomes, grow every day, and work with a team that wins together. Aplo is the only EU-registered crypto prime broker for institutional investors offering transparent, conflict-free, self-service execution with fast asset listing across hundreds of coins....


  • Paris, France Ekkiden Temps plein

    **Le rôle**: Local Information Security Officer (F/M)**: **Responsabilités: ***: - You will assist the central CISO team in identifying, managing and mitigating information security risks - You will prepare information security reports requested by the CISO - You will be monitor and report on the progress in the execution of the corrective and preventive...